Xls.Malware.Sload-7135989-0 — RTF malware analysis

Static analysis result for SHA-256 03e5d9fc07a5e231…

MALICIOUS

RTF

789.6 KB Created: 2018-07-17 14:59:00 First seen: 2019-04-17
MD5: b203040e92636d66bd5a5e5588b4a2d8 SHA-1: 7af57aaa7d414b5c6d2e15c9bfe31202c059396b SHA-256: 03e5d9fc07a5e2313ac94b83ecd836b9a8e5c22450ace28a775da0f88e2a6b6d
242 Risk Score

Malware Insights

Xls.Malware.Sload-7135989-0 · confidence 95%

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1203 Exploitation for Client Execution

The RTF file contains multiple embedded OLE objects, with heuristics indicating that \objupdate forces OLE activation and the presence of Composite Monikers. ClamAV detections identify the file as 'Xls.Malware.Sload-7135989-0', suggesting it's a malicious Excel-related threat. The embedded OLE objects are the primary mechanism for executing the malicious payload.

Heuristics 6

  • Composite Moniker in RTF OLE object high CVE related RTF_COMPOSITE_MONIKER_RELATED
    RTF contains Composite Moniker CLSID in OLE object context, but no nearby scriptlet/SCT payload was confirmed. Treat as related moniker attack-surface evidence rather than proof of CVE-2017-8570 exploitation.
  • ClamAV: Xls.Malware.Sload-7135989-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Malware.Sload-7135989-0
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 10 \objdata section(s) — embedded OLE objects
  • Embedded OLE object medium RTF_OBJEMB
    RTF contains \objemb — embedded OLE object
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://schemas.microsoft.com/office/word/2003/wordml In RTF body

Extracted artifacts 10

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00003c27.bin rtf-objdata-decoded RTF \objdata at offset 0x3C27 27195 bytes
SHA-256: e397832b19fc069706a75a11f4971e6b448d03befdc8867fc44411c173707c18
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_01_off00016892.bin rtf-objdata-decoded RTF \objdata at offset 0x16892 27195 bytes
SHA-256: 13a886e6457d3e1d4b1505875b1eb82f28f9c94fb7a18e798f9c93b9a4d17ff1
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_02_off000294fd.bin rtf-objdata-decoded RTF \objdata at offset 0x294FD 27195 bytes
SHA-256: 4bf98e9e1f72eed3d1161ad878a551c1548ee4683401d5485be8b0aa9ac9ad9e
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_03_off0003c168.bin rtf-objdata-decoded RTF \objdata at offset 0x3C168 27195 bytes
SHA-256: a5854cc4b1af3dbd6d369f4fe673db4703167b855a68b64dde7a3175e11f2600
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_04_off0004edd3.bin rtf-objdata-decoded RTF \objdata at offset 0x4EDD3 27195 bytes
SHA-256: 4e2edb0f6ed7121d920117120c15d6590d0e151b0957936f42bf39ce31a7b73e
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_05_off0006284e.bin rtf-objdata-decoded RTF \objdata at offset 0x6284E 27195 bytes
SHA-256: 0ebbae0fa23eb45da238fe2d10695f397593438f6ad10a50acdc70c2ecb7f7eb
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_06_off000754d8.bin rtf-objdata-decoded RTF \objdata at offset 0x754D8 27195 bytes
SHA-256: 42d462160ce3f51fb40c47fd0cc0cb1aae190d2aaf3ea00ab283fa075f4d94a4
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_07_off00088164.bin rtf-objdata-decoded RTF \objdata at offset 0x88164 27195 bytes
SHA-256: 34fc79597ffc8c49018b9faeeba0392a111d6008b1850a6a044d3397b7dfa952
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_08_off0009adf0.bin rtf-objdata-decoded RTF \objdata at offset 0x9ADF0 27195 bytes
SHA-256: da18d90d7a884a0a2ef3c72d08582faf4aaf6cd8b2bb78f56a7250b45f91ce08
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely
objdata_09_off000ada7c.bin rtf-objdata-decoded RTF \objdata at offset 0xADA7C 27195 bytes
SHA-256: ac83a949446f50cff82f3948129fcba3d0fd675f10a8280e8bf9b95fea0c3cc2
Detection
ClamAV: Xls.Malware.Sload-7135989-0
Obfuscation or payload: unlikely